Terms of Service
Last updated: 2026-08-20
These terms are a contract between you and 3A Labs LLC, a Texas limited liability company trading as Tenet ("Tenet", "we", "us").
There are three parts, and only some of them apply to you:
- Part A — everyone, including anyone just reading choosetenet.com
- Part B — business customers who integrate the Tenet verification service
- Part C — individuals who are sent through a verification flow, or who use the wallet
If you are a business customer with a separately signed agreement with us, that agreement wins wherever it differs from Part B.
Part A — Everyone
A1. Using this website
You may read, link to, and quote choosetenet.com. You may not scrape it at a volume that degrades it for others, attempt to break into it, or use it to build a competing product's marketing copy verbatim.
A2. Our intellectual property
The Tenet name, the threshold mark, the site's design, and its content are ours. Nothing here grants you a licence to use our trade marks. Documentation and code we publish under an open licence carry that licence, which governs instead.
A3. Nothing here is a warranty about the service
Marketing copy describes what the product is for. Part B is what we are actually contractually promising. Where a page on our website and these terms disagree, these terms govern.
Part B — Business customers
B1. What we provide
Tenet provides an age and identity assurance service: you send a person to our hosted verification flow, we determine whether they meet a threshold you set, and we return the answer — the answer, not the evidence. Depending on configuration this may use AI age estimation, government document verification with face matching, or a cryptographic proof from a digital wallet.
We provide it to you through our published HTTP API and our hosted flow. We may improve, change, or add methods, and we will not remove a method you depend on without reasonable notice.
B2. Your account and your keys
You get API keys. Treat them as passwords. You are responsible for everything done with your keys, including by your staff and contractors. Tell us immediately at security@choosetenet.com if a key is exposed, and rotate it — you can do this yourself, and you should not wait for us.
You will keep your account details accurate, and you will not share access with anyone outside your organisation without our written agreement.
B3. The division of legal responsibility — read this one
This clause allocates the obligations that regulators actually enforce, so it is written plainly rather than defensively.
You are the controller. We are the processor. You decide that a verification happens, who is subjected to it, and what threshold applies. We carry out your instruction.
You are the regulated party. If a regulator, an attorney general, or a court asks whether the people you admitted were age-assured, they will ask you. Our DPA and our attestation mechanism exist to let you answer.
You warrant that:
- you have a lawful basis to have each person verified, and you have given them whatever notice the law where they are requires;
- you will not send us anyone you know or suspect to be under 13, except where you are using the service precisely to find that out;
- you will present our flow honestly, and will not misdescribe what it does;
- your own privacy notice tells people that a third-party verification provider is used; and
- you will comply with the age-verification, biometric privacy, and data protection laws that apply to you.
We warrant that we will process personal data only on your documented instructions, maintain the security measures described on our Security page, and not use your data or your users' data to train models or for any purpose other than providing the service.
B4. Acceptable use
You will not use the service:
- to verify anyone without their knowledge, or through a flow designed to obscure what is happening;
- to build a profile of a person beyond the answer you asked for;
- to unlawfully discriminate against anyone;
- to attempt to recover a source image, a biometric template, or any input from a result we return;
- to test, probe, or attack the service outside a security disclosure we have agreed to; or
- in breach of any law that applies to you.
Consequence. Serious or repeated breach lets us suspend your access immediately. We will tell you why, and we will restore access when it is fixed. We would rather call you than switch you off, and normally will.
B5. Fees
Fees, volumes, and payment terms are in your order form or signed agreement. Absent one: fees are payable within 30 days of invoice, are exclusive of tax, and are non-refundable except where these terms say otherwise. Late amounts accrue interest at 1.5% per month or the maximum the law allows, whichever is lower.
We may change pricing on 60 days' written notice, effective at your next renewal.
B6. Your data, and what we do with it
Your data is yours. We claim no ownership over it.
Our handling of personal data is governed by the DPA, which is incorporated into these terms by reference. In summary, and consistently with it: verification images are never persisted; an immutable decision record is retained for seven years; we do not sell data; and we do not train models on your data or your users' data.
We may use aggregated, de-identified statistics — volumes, latencies, error rates — to operate and improve the service. These cannot identify you or any individual, and we will not publish anything that identifies you as a customer without your permission.
B7. Availability
We aim for high availability and will not pretend to a number we have not yet measured. No service level commitment is offered under these standard terms. Availability commitments are agreed with individual customers at contract time; where one is agreed in a signed order form, it governs over this section. We would rather negotiate a number we can hold than publish one we have not measured.
Planned maintenance will be notified in advance where practicable. Emergency maintenance may not be.
B8. Third-party services
The service depends on the providers listed on our Security page. We are responsible for them as our sub-processors under the DPA. We are not responsible for services you choose to connect to the results we send you.
B9. Warranties and disclaimers
We warrant that the service will perform materially as described in our documentation.
Beyond that, and to the fullest extent the law allows, the service is provided "as is". We disclaim all other warranties, express or implied, including merchantability, fitness for a particular purpose, and non-infringement.
Two disclaimers specific to what this product is, and both are honest rather than tactical:
- Age estimation is an estimate. AI age estimation returns a probabilistic answer with a confidence score, not a certainty. You configure the threshold. You accept that a correctly functioning system will still be wrong about some people in both directions.
- Document verification detects known signals of forgery. It is good. It is not infallible, and a sufficiently sophisticated forgery may pass.
We do not warrant that using Tenet makes you compliant with any law. We give you a capable tool and a provable record. Compliance is a property of your whole operation, and we cannot see most of it.
B10. Limitation of liability
Neither party is liable for indirect, incidental, special, consequential, or punitive damages, or for lost profits, revenue, data, or goodwill, even if warned they were possible.
Each party's total liability arising out of these terms is capped at the fees you paid or owed us in the 12 months before the claim. There is no floor beneath that figure.
These caps do not apply to: your obligation to pay fees; a party's breach of its confidentiality obligations; or fraud, wilful misconduct, or anything else the law does not permit us to limit.
Indemnity obligations and a breach of the DPA's security obligations sit inside this cap.
B11. Indemnities
We will defend you against a third-party claim that the service as provided by us infringes a US patent, copyright, or trade mark, and pay damages finally awarded. This does not apply where the claim arises from your data, your configuration, or your use of the service in breach of these terms.
You will defend us against a third-party claim arising from your data, your use of the service in breach of these terms or of law, or your failure to give a person the notice or obtain the consent that section B3 requires.
Each side must be told promptly, given control of the defence, and given reasonable cooperation.
B12. Confidentiality
Each side will protect the other's non-public information with at least reasonable care, use it only to perform these terms, and disclose it only to people who need it and are bound to equivalent terms. This does not cover information that is public, independently developed, or lawfully received from someone else. Compelled disclosure is permitted with prompt notice where lawful.
B13. Term, suspension, termination
These terms run while you use the service.
Either side may terminate for material breach not cured within 30 days of written notice, or immediately if the other becomes insolvent.
We may suspend immediately for a security risk, a legal requirement, or a serious acceptable-use breach.
On termination: your access stops, you pay what you owe, and we delete or return your data within 90 days on request — except the immutable audit records described in the DPA, which we cannot delete. Sections that by their nature should survive, do.
B14. Changes to these terms
We may update these terms. For material changes affecting business customers we will give at least 30 days' notice by email or in-product. Continuing to use the service after that means you accept them. If you do not, you may terminate before they take effect and we will refund any prepaid unused fees.
B15. General
Governing law: Texas, without regard to conflict-of-laws rules.
Disputes are arbitrated. Any dispute arising out of or relating to Part B, or to the Data Processing Agreement, is resolved by binding arbitration before a single arbitrator under the Commercial Arbitration Rules of the American Arbitration Association, seated in Williamson County, Texas. The Federal Arbitration Act governs this agreement to arbitrate. Judgment on the award may be entered in any court of competent jurisdiction.
Two things stay out of arbitration. Either party may seek temporary or preliminary injunctive relief, in a court of competent jurisdiction, to protect its intellectual property or confidential information pending arbitration; and either party may bring an individual claim in small-claims court where the claim qualifies.
Neither party may assign without the other's consent, except in a merger or sale of substantially all assets. Nothing here creates a partnership or agency. If a provision is unenforceable, the rest survives. Failure to enforce is not a waiver. These terms plus the DPA plus any order form are the entire agreement.
Neither party is liable for delay caused by events genuinely beyond its reasonable control.
Part C — Individuals being verified, and wallet users
C1. What this costs you
Nothing. The business that sent you is our customer. You are not.
C2. What we ask of you
Verify yourself, honestly. Do not use someone else's document, present an image of another person, or attempt to defeat the check. Do not attack the service.
If you are under 13, please do not use the wallet.
C3. What you can expect from us
We will tell you what a method involves before you use it. We will not store your selfie or your ID images. We will not sell your information. We will not treat a check that does not conclude as a judgment about you — an inconclusive result is an ordinary next step, not a verdict.
Where a method is available that sends us less about you, we will offer it and say what each one costs you.
C4. The wallet
The Tenet wallet is non-custodial, and the consequences are real:
- The private key is generated inside your device's security chip and cannot be extracted. Not by you, not by us, not by anyone with a warrant.
- We cannot recover it. There is no key escrow, no backup, no reset. This is deliberate: a key we could recover is a key that could be taken from us.
- If you lose your device, you re-verify and are issued a fresh credential. You do not lose your identity; you lose a card and get a new one.
- Credentials expire. When one does, you re-verify. We will never silently re-issue one on your behalf.
The wallet is provided free and as-is. We do not guarantee that a given business will accept a given credential — that is their decision.
C5. Your rights
See the Privacy Policy. In short: you may ask what we hold and ask us to delete it, with the one documented exception of the immutable decision record, which we explain rather than hide.
C6. Disputes
If a check went wrong, tell the business that sent you first — they can usually fix it immediately. If that fails, email support@choosetenet.com and we will look at the decision record.
Contact
legal@choosetenet.com — legal and contractual privacy@choosetenet.com — privacy security@choosetenet.com — vulnerability reports
We do not operate a postal contact channel. Email is the only route that reaches us.